1. Controller
The controller for processing in PM Universe is:
- [Company name]
- Organisation number: [org. no.]
- Address: [address]
- Email: [email]
If your organisation uses PM Universe as a customer, the organisation may in some cases be the controller for the project data entered in the service, while [Company name] acts as a processor. Any processor relationship is then governed separately.
2. What data we process
Depending on how you use the service, the following data may be processed:
- Account details: email address, name (if provided), user ID and password (hashed, handled by the authentication service).
- Organisation and membership: which organisation and projects you belong to, and role (e.g. admin or member).
- Project data: data you or colleagues enter in PM Universe (planning, resources, budget, risks, status reports, etc.). Free-text fields may contain personal data if users enter it — users are asked to avoid unnecessary personal data.
- Technical data: session cookies, selected organisation (`org_id`), and a local browser timestamp for idle sign-out.
- Sign-in via SSO (optional): if the organisation has enabled Google or Microsoft sign-in, name and email may be received from the identity provider at sign-in.
3. Purposes and legal basis
| Purpose | Legal basis |
|---|---|
| Provide the account, sign-in and permissions | Contract (use of the service) / legitimate interest in delivering the service |
| Store and display project data within your organisation | Contract / processor assignment |
| Send invitation and password-reset emails | Contract / legitimate interest |
| Security (session, idle sign-out, access control) | Legitimate interest |
| Traffic statistics on public pages (Google Analytics), only after consent | Consent |
We do not use personal data for marketing profiles or advertising networks. Analytics runs only if you accept analytics cookies.
4. Cookies and similar technologies
Necessary cookies are set without consent. Analytics cookies (Google Analytics) are set only if you approve them via the cookie banner.
Necessary cookies
| Name / type | Purpose | Storage |
|---|---|---|
| sb-*(Supabase Auth) | Keep you signed in and sync the session between server and browser (`httpOnly` where applicable) | Session / per Auth |
| org_id | Remember the selected organisation in multi-tenant mode (`httpOnly`, SameSite=Lax) | 30 days |
| analytics_consent | Remember your choice about analytics cookies (granted/denied) | 1 year |
Analytics cookies (after consent)
With consent, Google Analytics 4 is loaded on public pages (Google cookies, e.g. `_ga`). IP anonymisation is enabled in the configuration. You can change or withdraw your choice at any time via the controls below, via the “Change cookie settings” link in the footer on public pages, or by clearing the `analytics_consent` cookie.
Read more about how Google uses data: How Google uses data.
Manage cookie settings
Loading your cookie settings…
Local storage (not a cookie)
| Key | Purpose |
|---|---|
| pm_idle_last_activity | Sync last activity across tabs so idle sign-out (about 30 minutes) works correctly |
Fonts are loaded via Next.js (`next/font`) and hosted with the app — no separate tracking cookie from a font vendor is used in the client for this.
5. Recipients and sub-processors
To run the service, the following categories of providers are used. They may only process data under contract and for the stated purposes:
- Supabase — authentication, database (Postgres), RLS and auth-related emails (invite, password reset). Data is stored in an EU region (eu-west-1 per the service’s security documentation).
- Vercel — hosting and running the web application (including server functions and operational logs).
- Google / Microsoft — only if SSO is enabled for your organisation; authentication then goes via the respective identity provider.
- Google Analytics — only after cookie consent; traffic statistics on public pages.
- Stripe — payments and subscriptions when the organisation upgrades from trial. Card details are handled by Stripe (PCI); we store customer/subscription IDs.
AI (Anthropic): An SDK exists in the codebase for future features but is not actively used in the app today. No user data is sent to Anthropic while AI features are not enabled. If that changes, this policy will be updated.
We do not sell personal data and do not share it with advertising networks.
6. Transfers outside the EU/EEA
Primary storage of application data is within the EU via Supabase (eu-west-1). The hosting provider Vercel may process technical data (e.g. request logs) in multiple regions. With SSO, Google or Microsoft may process authentication data under their terms, which may involve transfers outside the EU/EEA with appropriate safeguards (e.g. standard contractual clauses) at each provider.
7. Retention
- Account details — for as long as the account is active, and thereafter until the account is deleted by an administrator or on request.
- Project data — for as long as the organisation uses the service, or until data is deleted by an authorised user/admin. After cancellation or an expired trial there is normally a 14-day export window, after which the workspace is locked. Data may be retained for up to 90 days for reactivation before it can be deleted (see also Danger zone under Settings).
- org_id cookie — 30 days (or until cleared).
- Session — per Supabase Auth; the app also signs you out after about 30 minutes of inactivity.
- Technical logs — per each provider’s retention (Vercel/Supabase).
8. Your rights
Under the GDPR you have, among other things, the right to:
- access to your personal data
- rectification of inaccurate data
- erasure ("the right to be forgotten") where applicable
- restriction of processing
- data portability where applicable
- object to processing based on legitimate interest
- lodge a complaint with the Swedish Authority for Privacy Protection (IMY)
Under Settings, an organisation admin can delete the entire organisation (including project data), and you can delete your own account (provided you are not the sole admin of a remaining organisation). Org admins can also download a ZIP export of organisation data (JSON/CSV) while the account is active or during the export window after cancellation. For other requests, contact [email].
Transactional emails about trial, cancellation and export reminders may be sent via our email provider (Resend). Payment-related emails (invoice, receipt) are sent by Stripe when payment is enabled.
9. Security
Access to data is limited with row-level security (RLS) per organisation, encryption in transit, and password handling via Supabase Auth. Session cookies are synced on the server side. In case of a suspected personal data breach, notification to IMY is assessed under applicable rules (within 72 hours when required).
10. Children
The service is aimed at professional project management and is not intended for children under 16.
11. Changes
We may update this policy when the service or legal requirements change. The current version is published on this page with the date of the latest update. Material changes (e.g. new tracking tools or AI processing) will be communicated clearly.
12. Contact
Questions about personal data or exercising your rights:
- Email: [email]
- Controller: [Company name] ([org. no.])